You are not too small for a SOC.
You are too small to staff one.
Covering every hour of the year takes five analysts before you have any resilience. That arithmetic, not the technology, is why this is bought rather than built.
A year contains 8,760 hours. One full-time analyst covers roughly 1,800 of them once leave and training are counted. Covering every hour therefore takes five or more people before you have any cover for sickness, holidays or somebody resigning.
No company of 150 people solves that by hiring. It is why a security operations centre is bought as a service, and it is the whole argument.
What you should be comparing is not whether to outsource, but what the outsourced version actually does when something fires. The line that matters is whether the SOC acts (isolating a host, disabling an account, revoking a token) or whether it emails you an alert with a severity label and waits.
Why three shifts
is five people.
hours in a year that need covering if the answer is 24/7/365
hours one full-time analyst actually works, after leave and training
analysts before you have cover for holidays, sickness and attrition
This is division, not a sales argument. You can run the same numbers against your own payroll and reach the same place. And the headcount is only the start: the people have to be trained, kept current, given tooling, and covered when one of them leaves, which in this field happens more often than in most.
The alternative most small companies actually choose is a partial answer: endpoint software that nobody watches overnight, and an assumption that the important alerts will still be there on Monday. Usually they are. Occasionally the whole weekend mattered.
Four questions
worth asking anyone.
Ask these of us and of everyone else you talk to. The answers separate products that look identical on a feature grid.
Does the SOC act, or does it advise?
This is the question that separates managed detection from alert forwarding. Ask whether they will isolate a host or disable an account at 3am without calling you first, and at which tier that starts. An emailed alert with a severity label is not a response.
Is identity in scope, or only endpoints?
Small companies are overwhelmingly compromised through accounts. If Active Directory, Entra ID and Microsoft 365 are not being watched and correlated with endpoint activity, the most likely intrusion path is the one nobody is looking at.
Who actually reads it at 3am, and where are they?
Ask whether the overnight shift is staffed by analysts or by an escalation rota with a pager. Both are legitimate answers, but they are different products and only one of them is a SOC.
What happens to your existing IT provider?
A good answer is that nothing happens to them. Most small companies already have an MSP and the cleanest arrangement is usually that they keep the relationship while the SOC runs behind them.
The SOC acts.
It does not advise.
ThreatDefend™ is Vijilan’s stack and Vijilan’s SOC. We bring CrowdStrike Falcon, deploy it, and run it around the clock with Tier 1 through Tier 3 analysts on every alert. When something is real we contain it: host isolation, account disable, token revoke, process kill, from the entry tier rather than the one above.
Identity is included from Essential, which is less common than it sounds. Active Directory, Entra ID and Microsoft 365, correlated with endpoint activity, because a stolen session token does not trip an endpoint sensor.
Praxis AI™ investigates, correlates and triages before a human sees it, so the analyst starts with context rather than a raw detection. A trained analyst authorizes every consequential action. Never autonomous-only, and that is a deliberate decision about accountability.
See what an attacker sees before you scope a SOC.
ThreatAssess™ is a free external attack surface assessment. A domain is all we need, with no agent and no credit card. It makes the first conversation about your actual exposure rather than a generic deck.
The ones people
actually ask.
What is a managed SOC for a small business?
A security operations centre run by somebody else, watching your environment around the clock, with analysts who investigate what fires and act on what is real. For a company of 25 to 250 people it replaces a function you would otherwise have to staff with at least five people to cover every hour of the year.
How many people does it take to run a 24/7 SOC in-house?
More than most small companies expect. A year contains 8,760 hours and one full-time analyst covers roughly 1,800 of them once leave and training are accounted for. Covering every hour therefore takes five or more analysts before you have any resilience for sickness, holidays or somebody resigning. That arithmetic, rather than the technology, is why this is bought as a service.
What is the difference between a managed SOC and an MSP?
An MSP runs your IT: devices, users, applications, the helpdesk. A managed SOC watches for and responds to security incidents specifically, around the clock. They are complementary rather than competing, and most of the companies Vijilan protects have both. We run the SOC behind the provider and never compete with our partners for their clients.
Can we keep our IT provider and still get a SOC?
Yes, and it is usually the cleanest outcome. If your provider is already a Vijilan partner we work through them. If they are not, we will talk to them. If you have no provider, or security sits outside what yours does, we will run it directly.
What should a small business expect a managed SOC to actually do?
Watch every hour, investigate what fires rather than forwarding it, and act when something is real: isolating a host, disabling an account, revoking a token, killing a process. Then tell you what happened and what was done, in language that makes sense to somebody who is not a security engineer.
Related reading
- MDR for small businessEDR is the software. MDR is somebody answering when it fires.Read
- Do you need a SIEM yet?Often not. The two questions that actually settle it.Read
- CrowdStrike for small businessWhere Falcon Go stops, and who operates it after the license.Read
- ThreatDefendThe four tiers, and what the SOC does at each one.Read